The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuring the detection thresholds for reconnaissance events (CLI)

Prev Next

When the IPS-enabled engine detects a certain number of failed network connections to or from the same IP address occurring within a rolling 60‑second window, a reconnaissance attack is suspected. Based on this and other criteria, the engine determines whether the suspicious activity constitutes a reconnaissance event.

The system initializes with default threshold values for ping sweep detection and port scan detection. You can configure higher thresholds to reduce false positive IPS events.

Prerequisites
Procedure
To configure IPS detection thresholds for reconnaissance activity:
  1. Enable the CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Check the current status of the feature. In the following example, the feature is enabled with default values.

    hostname (config) # show ips reconnaissance
    Ping sweep threshold  : 20
    Port scan threshold   : 200
    Brute force threshold : 5
  3. Configure a new ping sweep threshold value. In the following example, the threshold is raised to 35.

    hostname (config) # ips ping-sweep threshold 35
  4. Configure a new port scan threshold value. In the following example, the threshold is raised to 300.

    hostname (config) # ips port-scan threshold 300
  5. Confirm your changes.

    hostname (config) # show ips reconnaissance
    Ping sweep threshold  : 35
    Port scan threshold   : 300
    Brute force threshold : 5
  6. Save your changes.

    hostname (config) # write memory